ืขื“ื›ื•ืŸ OpenSSL 1.1.1j, wolfSSL 4.7.0 ื•-LibreSSL 3.2.4

ื’ืจืกืช ืชื™ืงื•ืŸ ืฉืœ ืกืคืจื™ื™ืช ื”ืงืจื™ืคื˜ื•ื’ืจืคื™ื” OpenSSL 1.1.1j ื–ืžื™ื ื” ื›ืขืช, ื•ืชื•ืงื ืช ืฉืชื™ ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2021-23841 - ื”ืกืจืช ื”ืคื ื™ื” ืฉืœ ืžืฆื‘ื™ืข NULL ื‘ืคื•ื ืงืฆื™ื” X509_issuer_and_serial_hash() ืขืœื•ืœื” ืœื’ืจื•ื ืœืงืจื™ืกื” ืฉืœ ื™ื™ืฉื•ืžื™ื ื”ืงื•ืจืื™ื ืœืคื•ื ืงืฆื™ื” ื–ื• ื›ื“ื™ ืœืขื‘ื“ ืื™ืฉื•ืจื™ X509 ืขื ืขืจืš ืฉื’ื•ื™ ื‘ืฉื“ื” ื”ืžื ืคื™ืง.
  • CVE-2021-23840 - ื’ืœื™ืฉื” ืฉืœ ืžืกืคืจ ืฉืœื ื‘ืคื•ื ืงืฆื™ื•ืช EVP_CipherUpdate, EVP_EncryptUpdate ื•-EVP_DecryptUpdate ืขืœื•ืœื” ืœื’ืจื•ื ืœืขืจืš ืžื•ื—ื–ืจ ืฉืœ 1, ื”ืžืฆื™ื™ืŸ ื”ืฆืœื—ื”, ื•ืœืขืจืš ืฉืœื™ืœื™ ืขื‘ื•ืจ ื”ื’ื•ื“ืœ, ืžื” ืฉืขืœื•ืœ ืœื’ืจื•ื ืœื™ื™ืฉื•ืžื™ื ืœืงืจื•ืก ืื• ืœื”ืชื ื”ื’ ื‘ืฆื•ืจื” ืœื ืชืงื™ื ื” ืื—ืจืช.
  • CVE-2021-23839 - ืคื’ื ื‘ื™ื™ืฉื•ื ื”ื’ื ืช ื’ื™ื‘ื•ื™ ืœืฉื™ืžื•ืฉ ื‘ืคืจื•ื˜ื•ืงื•ืœ SSLv2. ืžืฉืคื™ืข ืจืง ืขืœ ืขื ืฃ 1.0.2 ื”ื™ืฉืŸ ื™ื•ืชืจ.

LibreSSL 3.2.4 ืฉื•ื—ืจืจื” ื’ื ื”ื™ื, ื•ื”ื™ื ืžื™ื™ืฆื’ืช ืืช ื”ืžื–ืœื’ ืฉืœ OpenSSL ื‘ืคืจื•ื™ืงื˜ OpenBSD, ืฉืžื˜ืจืชื• ืœืกืคืง ืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื” ื™ื•ืชืจ. ืžื”ื“ื•ืจื” ื–ื• ื‘ื•ืœื˜ืช ื‘ื—ื–ืจืชื” ืœืงื•ื“ ืื™ืžื•ืช ื”ืื™ืฉื•ืจื™ื ื”ื™ืฉืŸ ืฉืฉื™ืžืฉ ื‘-LibreSSL 3.1.x, ืขืงื‘ ื™ื™ืฉื•ืžื™ื ืžืกื•ื™ืžื™ื ืฉื”ืกืชืžื›ื• ืขืœ ืงื™ืฉื•ืจื™ื ื›ื“ื™ ืœืขืงื•ืฃ ื‘ืื’ื™ื ื‘ืงื•ื“ ื”ื™ืฉืŸ. ื‘ื™ืŸ ื”ืชื›ื•ื ื•ืช ื”ื—ื“ืฉื•ืช, ื‘ื•ืœื˜ืช ืชื•ืกืคืช ืฉืœ ืžื™ืžื•ืฉื™ื ืฉืœ TLSv1.3 ืฉืœ ืจื›ื™ื‘ื™ ื”ื™ืฆื•ืืŸ ื•ื”ืฉืจืฉืจืช ื”ืื•ื˜ื•ืžื˜ื™ืช.

ื‘ื ื•ืกืฃ, ื™ืฆืื” ื’ืจืกื” ื—ื“ืฉื” ืฉืœ ืกืคืจื™ื™ืช ื”ืงืจื™ืคื˜ื•ื’ืจืคื™ื” ื”ืงื•ืžืคืงื˜ื™ืช wolfSSL 4.7.0. ื”ื™ื ืžื•ืชืืžืช ืœืฉื™ืžื•ืฉ ื‘ืžื›ืฉื™ืจื™ื ืžืฉื•ื‘ืฆื™ื ืขื ืžืฉืื‘ื™ ืžืขื‘ื“ ื•ื–ื™ื›ืจื•ืŸ ืžื•ื’ื‘ืœื™ื, ื›ื’ื•ืŸ ืžื›ืฉื™ืจื™ IoT, ืžืขืจื›ื•ืช ื‘ื™ืช ื—ื›ื, ืžืขืจื›ื•ืช ืžื™ื“ืข ื‘ืจื›ื‘, ื ืชื‘ื™ื ื•ื˜ืœืคื•ื ื™ื ื ื™ื™ื“ื™ื. ื”ืงื•ื“ ื ื›ืชื‘ ื‘ืฉืคืช C ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžื™ื™ืฉืžืช ืชืžื™ื›ื” ื‘-RFC 5705 (ื™ืฆื•ืื ื™ ื—ื•ืžืจื™ ืžืคืชื— ืขื‘ื•ืจ TLS) ื•ื‘-S/MIME (ื”ืจื—ื‘ื•ืช ื“ื•ืืจ ืื™ื ื˜ืจื ื˜ ืžืื•ื‘ื˜ื—ื•ืช/ืจื‘-ืชื›ืœื™ืชื™ื•ืช). ื”ื“ื’ืœ "--enable-reproducible-build" ื ื•ืกืฃ ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ื‘ื ื™ื•ืช ื—ื•ื–ืจื•ืช. ืžืžืฉืงื™ ื”-API ืฉืœ SSL_get_verify_mode, X509_VERIFY_PARAM ื•-X509_STORE_CTX ื ื•ืกืคื• ืœืฉื›ื‘ืช ื”ืชืื™ืžื•ืช ืฉืœ OpenSSL. ื”ืžืืงืจื• WOLFSSL_PSK_IDENTITY_ALERT ื™ื•ืฉื. ื”ืคื•ื ืงืฆื™ื” ื”ื—ื“ืฉื” _CTX_NoTicketTLSv12 ื ื•ืกืคื” ื›ื“ื™ ืœื”ืฉื‘ื™ืช ื›ืจื˜ื™ืกื™ ื”ืคืขืœื” ืฉืœ TLS 1.2 ืืš ืœืฉืžืจ ืื•ืชื ืขื‘ื•ืจ TLS 1.3.

ืžืงื•ืจ: OpenNet.ru

ืงื ื” ืื™ืจื•ื— ืืžื™ืŸ ืœืืชืจื™ื ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS ๐Ÿ”ฅ ืงื ื” ืื—ืกื•ืŸ ืืชืจื™ื ืืžื™ืŸ ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS | ProHoster